SOC Detection Expert

il y a 2 semaines


Paris, Île-de-France AXA France Temps plein

Job Description:About the jobJob purposeSecurity Operations Center (SOC) delivers the following capabilities to the AXA entities around the globe: Security Incident Detection, Threat Hunting, Security Incident Response and Threat Intelligence.Highly skilled SOC Detection Expert with a deep understanding of detection engineering is responsible for designing, developing, and implementing detection use cases to increase AXA threat detection capability and meet stakeholder requirements. The role also requires being conversant with performing complex data manipulations and analysis.Main missionsAdversary Emulation Capability Leadership:Design/Implement automated attack scenarios to validate SOC readiness under realistic threat conditions.Provide expert support to SOC teams, Use Case Factory, and AXA entities by incorporating their needs and feedback into platform capabilities and scenario design.Lead the definition, delivery, and hands-on development of new platform features, guiding the team's architectural decisions and prioritizing enhancements to ensure the solution matures in accuracy, scalability, and security.Continuously integrate insights gained from adversary emulation into enhanced detection logic.Detection Engineering: Design, implement, and optimize detection use cases, rules, and algorithms within SIEM, EDR, and other detection platformsDocumentation & Knowledge Sharing: Document detection strategies, rules, and processes, and share knowledge with SOC teams to improve overall operational readiness.Metrics & Reporting: Develop and report on key performance indicators (KPIs) related to detection efficiency, effectiveness, and coverage to senior managementTechnology Evaluation: Stay abreast of emerging technologies and trends in cybersecurity, leading the evaluation and implementation of new tools and techniques that enhance detection capabilitiesExpected skills & experienceWe are looking for someone with the following experience and skills:ExperienceExperience in Information Security > 2 yearsExperience in DevSecOps > 2 yearsTechnical skillsAdvanced Python scripting and development capabilities (familiarity with Django is a plus)Proven track record in adversary emulation and security control validationSolid understanding of detection engineering concepts and MITRE ATT&CKFamiliarity with different security attack vectors and means of protectionProficiency in Microsoft Sentinel and Kusto Query Language (KQL)Strong problem-solving skills with the ability to troubleshoot and resolve complex issuesAbility to work independently and as part of a team in a fast-paced environmentExcellent written and verbal communication skills (Fluent in English)EducationUniversity degree in information security or equivalent work experienceWhat we offerWe bring together the expertise, cultural diversity and creativity of over 8,000 employees worldwide and we're committed to equal opportunities in all aspects of employment (gender, LGBT+, disabled persons, or people of different origins) and to promoting Diversity & Inclusion by creating a work environment where all employees are treated with dignity and respect, and where individual differences are valued.About the entityAXA is becoming a sustainable tech-led company and at AXA Group Operations we are one of the major catalysts for this transformation.We set the tone by triggering and empowering the evolution of our insurance business model through technology and innovation, driving its concrete implementation globally at speed, with a high quality of advisory and execution.We are present across 17 countries with committed, highly qualified teams. We leverage technology, data, sourcing, security and investment allocation in a global way, but also achieve economies of scale and synergies when necessary.At AXA Group Operations, we want to be recognized in three fields of action:State-of-the-art Data Technology to drive customer experienceState-of-the-art Procurement & Sourcing to drive efficiency and better manage risksHigh-Performing Global Team for stronger partnerships with AXA entitiesAbout AXAAs a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working for 105 million customers, we've created a truly dynamic and vibrant community. Inclusion and diversity link closely with our values, and together we're nurturing a culture of respect, for each other, for our customers and the communities around us. Join AXA and you'll feel like you belong, are included and can thrive. You'll be able to shape the way you work and truly grow your potential as you seek out new opportunities, push boundaries and benefit people in critical moments of their lives. This is your chance to build the tomorrow you want. Know you can.


  • ANALYSTE SOC SENIOR

    il y a 2 semaines


    Paris, Île-de-France CyberTee Temps plein

    Descriptif de mission ? Analyste SOC SENIORMissions:Intégration au Global SOC du groupe (centre d?excellence cybersécurité).Détection, analyse et gestion des incidents de sécurité issus du SIEM (Splunk), mails ou appels.Qualification des alertes et coordination avec les équipes sécurité locales.Évaluation des risques et mise en place de règles de...

  • Analyste SOC Confirmé

    il y a 2 semaines


    Paris, Île-de-France NEVERHACK Temps plein

    QUI SOMMES-NOUS ?NEVERHACKest un groupe français expert en cybersécurité depuis plus de 40 ans, présent dans 10 pays avec plus de 1 200 collaborateurs.Notre mission ?Construire un monde numérique plus sûr grâce à des solutions innovantes et éthiques.Notre offre :Conseil, formation, évaluation des risques, IA… nous accompagnons entreprises et...

  • Analyste SOC N3

    il y a 2 semaines


    Paris, Île-de-France eXalt Shield Temps plein

    Offre d'emploi pour un contrat en CDI au sein de l'entité Shield du groupe eXalt. Contexte de la mission :Vous interviendrez au sein de l'équipe d'Adrien sur des sujets tels que : Détection et traitement des incidents (SOC niveau 3 / Global SOC) Gestion EDR :Crowdstrike+ suivi Antivirus Intégration d'une nouvelle solution : Kaspersky Réponse à...

  • Team Lead, SOC

    il y a 4 jours


    Paris, Île-de-France Mistral Ai Temps plein

    About Mistral At Mistral AI, we believe in the power of AI to simplify tasks, save time, and enhance learning and creativity. Our technology is designed to integrate seamlessly into daily working life. We democratize AI through high-performance, optimized, open-source and cutting-edge models, products and solutions. Our comprehensive AI platform is designed...

  • Team Lead, SOC

    il y a 6 jours


    Paris, Île-de-France Mistral AI Temps plein

    About Mistral  At Mistral AI, we believe in the power of AI to simplify tasks, save time, and enhance learning and creativity. Our technology is designed to integrate seamlessly into daily working life. We democratize AI through high-performance, optimized, open-source and cutting-edge models, products and solutions. Our comprehensive AI platform is...

  • SOC Analyst

    il y a 6 jours


    Paris, Île-de-France KatchMe Temps plein

    Société :Entreprise technologique française en forte croissanceSpécialiste des infrastructures souveraines et durablesActeur clé de la deep tech, du cloud et de la cybersécuritéDatacenters situés en Europe et Amérique du NordEngagement fort pour une tech performante, éthique et éco-responsableMissionsSurveiller et investiguer les incidents de...

  • Analyste SOC N3

    il y a 1 semaine


    Paris, Île-de-France act digital Temps plein

    Description de l'entreprise Act digital est une société de conseil et d'expertise en technologies créée en 2011. Notre vocation est d'accompagner nos clients sur leurs enjeux de transformation numérique. Notre offre s'articule autour des expertises suivantes :Software DeliveryInfrastructure & Cloud ComputingAgile IT PerformanceBusiness PerformanceNous...

  • Expert Cortex XSIAM

    il y a 1 semaine


    Paris, Île-de-France Collective Temps plein

    ContexteDans le cadre du renforcement de la plateforme de détection et automatisation SecOps, nous recherchons un consultant expert Cortex XSIAM pour intervenir sur la phase Build & optimisation (playbooks, ingestion, use cases).Paris (2j onsite/sem) + Remote 3j600–650€ / jour selon profil Démarrage immédiat – Mission longue ( >12 mois)Expérience...

  • Expert Cortex XSIAM

    il y a 1 semaine


    Paris, Île-de-France Collective Temps plein 600 € - 650 €

    ContexteDans le cadre du renforcement de la plateforme de détection et automatisation SecOps, nous recherchons un consultant expert Cortex XSIAM pour intervenir sur la phase Build & optimisation (playbooks, ingestion, use cases). Paris (2j onsite/sem) + Remote 3j 600–650€ / jour selon profil Démarrage immédiat – Mission longue (>12 mois) Expérience...

  • Senior SOC Analyst

    il y a 4 jours


    Paris, Île-de-France SERMA Safety and Security Temps plein

    Company DescriptionSERMA Safety and Security, established in 2015, is a leading authority in ensuring the security and safety of products and systems. With expertise spanning cybersecurity, security evaluation, functional safety, and formal methods, the company delivers comprehensive consulting and evaluation services across the entire lifecycle of...